I am building a Copilot Studio agent that connects to a custom MCP server hosted in AWS Lambda. Below is my setup:
My Architecture
- I created an AWS Lambda that implements MCP (Model Context Protocol) functionality.
- In the Lambda, I generate my organization token using the Microsoft SSO token—I receive the SSO token in every request through the Authorization header.
- In Copilot Studio, I created:
- An Agent
- An MCP connector tool using “Extend your agent with Model Context Protocol”
- Added the server URL, Azure AD app client ID, and client secret to the connector tool
- Enabled Microsoft Teams channel for publishing the agent
- I then published the Copilot at organization level.
Problem
When I use the Copilot in Teams:
- Every time I start a new chat, Teams asks me to open Connection Manager and sign in again.
- The SSO token generated is valid for 2 hours, but Teams still forces re-authorization.
- When another user in my organization tries the bot, they also get the Connection Manager login required message on the first use.
- The expectation is: Teams should automatically provide each user’s token to my Lambda without manual connection each time.
Question
- Why is the Teams channel not automatically passing the user token to the MCP connector?
- Why does Copilot/Teams force the Connection Manager login again even though the SSO token and connector settings are correct?
- Is there an additional configuration needed so that new users automatically authenticate without opening Connection Manager manually?
- How can this issue be fixed so that the Copilot agent works seamlessly for all users?
Any guidance on correct SSO setup, connector configuration, or Teams channel configuration would be helpful.